Override Classes

Exactly Which Directives Each Class Permits

apache2ctl -L lists every directive your loaded modules define with its class (when AllowOverride includes Indexes): 238 here, 128 allowed in .htaccess. Two surprises: ExpiresActive needs Indexes, not FileInfo, and php_value needs Options and exists only under mod_php; with PHP-FPM (PHP-FPM via proxy_fcgi) it is a 500, so use .user.ini (php.ini and Extensions). A typical application file mixes four classes:

An application .htaccess that needs four override classesApache config
# /var/www/example/.htaccess - needs mod_rewrite, mod_headers and mod_expires
Options -Indexes
DirectoryIndex index.php index.html
ErrorDocument 404 /errors/404.html
Header always set X-Content-Type-Options "nosniff"
ExpiresActive On
ExpiresByType text/css "access plus 1 year"
<FilesMatch "\.(env|ini|log|sql|bak)$">
  Require all denied
</FilesMatch>
RewriteEngine On
RewriteRule ^old-blog/(.*)$ /blog/$1 [R=301,L]
RewriteCond %{REQUEST_FILENAME} !-f
RewriteRule ^ index.php [L]

Line 2 needs Options; lines 3, 6 and 7 need Indexes; lines 4, 5 and 11 to 14 need FileInfo; line 9 needs AuthConfig; the <FilesMatch> wrapper needs only a value other than None. So AllowOverride AuthConfig FileInfo Indexes Options is enough. With a one-line index.php that echoes REQUEST_URI:

Checking the headers and the front controllerShell
curl -si localhost:8104/site.css | grep -E '^(HTTP|Cache|Expires|X-)'
curl -s localhost:8104/products/42
Output
HTTP/1.1 200 OK
X-Content-Type-Options: nosniff
Cache-Control: max-age=31536000
Expires: Thu, 23 Sep 2027 07:40:52 GMT
front controller: /products/42

/backup.sql returns 403. Without Indexes, every request is a 500 with DirectoryIndex not allowed here; without AuthConfig, the log blames the wrapper: Require not allowed in <FilesMatch> context.